<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-8108277809937554792.post1834159605721978173..comments</id><updated>2008-08-23T18:29:06.852-05:00</updated><title type='text'>Comments on SteveCo: SELinux</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.stevecoinc.com/feeds/1834159605721978173/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8108277809937554792/1834159605721978173/comments/default'/><link rel='alternate' type='text/html' href='http://blog.stevecoinc.com/2008/08/selinux.html'/><author><name>Steven Pritchard</name><uri>http://www.blogger.com/profile/00716303018104544735</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>3</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8108277809937554792.post-2982833130247577936</id><published>2008-08-23T18:29:00.000-05:00</published><updated>2008-08-23T18:29:00.000-05:00</updated><title type='text'>Actually, when using SELinux you *cannot* use *-ch...</title><content type='html'>Actually, when using SELinux you *cannot* use *-chroot.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8108277809937554792/1834159605721978173/comments/default/2982833130247577936'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8108277809937554792/1834159605721978173/comments/default/2982833130247577936'/><link rel='alternate' type='text/html' href='http://blog.stevecoinc.com/2008/08/selinux.html?showComment=1219534140000#c2982833130247577936' title=''/><author><name>Matěj Cepl</name><uri>http://www.blogger.com/profile/13388318701398808404</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.stevecoinc.com/2008/08/selinux.html' ref='tag:blogger.com,1999:blog-8108277809937554792.post-1834159605721978173' source='http://www.blogger.com/feeds/8108277809937554792/posts/default/1834159605721978173' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-8108277809937554792.post-1673246317925980308</id><published>2008-08-22T11:51:00.000-05:00</published><updated>2008-08-22T11:51:00.000-05:00</updated><title type='text'>Hi Steve,I read this off of my Fedora planet feed,...</title><content type='html'>Hi Steve,&lt;BR/&gt;&lt;BR/&gt;I read this off of my Fedora planet feed, and I pretty much wanted to say that as a user-only member of the Fedora community (if you even want to call that being a member ...) I agree completely.  I really *want* to use SELinux, but it seems like at this point it just requires too much work and knowledge for someone that isn't running some mission critical server.&lt;BR/&gt;&lt;BR/&gt;I know that F9 made the first step in getting us lay-folk to use SELinux by enabling it by default, but too many things weren't working correctly so it just seemed easier to switch back to permissive mode and check my logs regularly.  I don't *like* that solution, and I know anyone with true Linux street cred would freak over it, but honestly when I try to convince friends and family that they, too, with far less computer experience than me, could make the switch to Fedora (esp. over Ubuntu) if they wanted to, I'm really kind of jumping the gun because features like SELinux aren't really ready yet for the layest of lay-folk.&lt;BR/&gt;&lt;BR/&gt;Obviously, being lazy, and having a limited skill set, I'd love to see a solution my where the packages I download just handle all my SELinux configuration and policy for me and I can expect full functionality *and* better security just by going with Fedora packages, but I can see where this demands too much of the maintainers.&lt;BR/&gt;&lt;BR/&gt;--John</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8108277809937554792/1834159605721978173/comments/default/1673246317925980308'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8108277809937554792/1834159605721978173/comments/default/1673246317925980308'/><link rel='alternate' type='text/html' href='http://blog.stevecoinc.com/2008/08/selinux.html?showComment=1219423860000#c1673246317925980308' title=''/><author><name>John Andrew Hanauer</name><uri>http://www.blogger.com/profile/05660489830389214179</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.stevecoinc.com/2008/08/selinux.html' ref='tag:blogger.com,1999:blog-8108277809937554792.post-1834159605721978173' source='http://www.blogger.com/feeds/8108277809937554792/posts/default/1834159605721978173' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-8108277809937554792.post-566272818414006330</id><published>2008-08-22T11:29:00.000-05:00</published><updated>2008-08-22T11:29:00.000-05:00</updated><title type='text'>Chroot is not a security tool.When you're using SE...</title><content type='html'>Chroot is not a security tool.&lt;BR/&gt;&lt;BR/&gt;When you're using SELinux you definitely don't need to chroot.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8108277809937554792/1834159605721978173/comments/default/566272818414006330'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8108277809937554792/1834159605721978173/comments/default/566272818414006330'/><link rel='alternate' type='text/html' href='http://blog.stevecoinc.com/2008/08/selinux.html?showComment=1219422540000#c566272818414006330' title=''/><author><name>Colin Walters</name><uri>http://www.blogger.com/profile/07005185411005194524</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.stevecoinc.com/2008/08/selinux.html' ref='tag:blogger.com,1999:blog-8108277809937554792.post-1834159605721978173' source='http://www.blogger.com/feeds/8108277809937554792/posts/default/1834159605721978173' type='text/html'/></entry></feed>